Lesson 4/7
Certificates and keys, explained for everyone
Understand digital certificates from A to Z: the vocabulary (public key, private key, CA, CSR), how HTTPS actually works with a worked scenario, the certificate chain, Let's Encrypt, and a demo on IIS/Exchange with key management.
☰
Contents
20
▾
0:00 Introduction - understanding certificates 0:25 The certificate: a digital identity card 0:47 The HTTPS padlock does not guarantee safety 1:07 Fingerprint and public key in the browser 1:43 Protocol, public key and private key 2:19 Certificate authority (CA) and encryption 2:44 HTTP vs HTTPS: data in the clear vs encrypted 3:10 SSL is obsolete, TLS 1.2 is the minimum 3:30 CSR: the certificate signing request 3:49 The private key: absolute secret and passphrase 4:04 Certificate stores (Windows, Azure, AWS, Linux) 4:40 The certificate chain and intermediates 4:58 Let's Encrypt and automatic renewal with Certbot 5:17 Worked scenario: the HTTPS handshake step by step 6:33 Session key and encrypted traffic 6:41 Windows demo: certificate authority and certlm 7:19 Certificate and private key on the server 7:43 Binding the certificate to IIS on port 443 8:05 Managing and exporting private keys 8:55 Conclusion